SAP Patches Max-Severity Commerce Cloud RCE Flaw

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- SAP patched CVE-2026-58231, a CVSS 10.0 flaw in SAP Commerce Cloud's Data Hub Adapter that lets unauthenticated attackers execute arbitrary code by abusing a default authentication client and submitting crafted input to functions lacking sufficient validation.
- Onapsis urged customers to patch to a fixed Commerce Cloud release and re-deploy, recommending an IP Filter Set workaround to restrict access to the vulnerable endpoint until the patch can be applied.
- SAP also addressed CVE-2026-44772 (CVSS 9.9) in Manufacturing Integration and Intelligence, where a low-privileged attacker can use a vulnerable servlet to trigger arbitrary command execution on the underlying host.
- SAP patched CVE-2026-34265 (CVSS 9.8), an out-of-bounds write in Application Server ABAP for SAP NetWeaver and ABAP Platform that exploits logical errors in DIAG protocol parsing to corrupt memory and potentially disclose sensitive system information.
- SAP fixed CVE-2026-44758 (CVSS 9.1), a code injection vulnerability in Manufacturing Integration and Intelligence involving server-side template injection (SSTI) and server-side request forgery (SSRF), by removing the vulnerable servlet component.
- The CVE-2026-44772 fix requires maintaining a new "Secure Transformer" system property listing allowed hosts for XSL files — a post-patch configuration step beyond the code update itself that administrators must not skip.
Why it matters: For organizations running SAP Commerce Cloud, this sits at the highest-severity tier: unauthenticated, remotely exploitable, full code execution with compromise of internal components. The unpatched endpoint threatens confidentiality, integrity, and availability simultaneously. With three additional critical flaws (CVSS 9.1–9.9) patched in the same August 2026 cycle, SAP administrators are looking at a stack of urgent items rather than a single fix-and-forget task.
Ask SkimNews




